STARBUCKS CORPORATION
ent_019fa5cca16bcfe129222a86d92f4fb2
Disclosures
10
Leak Site · State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,686
as filed · State AG MA
Leak-site claims
3
unverified actor claims
Identity resolution
- Canonical name
- STARBUCKS CORPORATION
- Normalized
- starbucks— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- OQSJ1DU9TAOC51A47K68
- SEC EDGAR CIK
- 0000829224
- Domain
- starbucks.com
Disclosure history (10)newest first
- GLOBALLeak Siteas victim2026-05-21
StarBucks Failed to reach out to us and didn't pay even $500,000 when we know they can afford it. It's not even that much we were asking for. Since you didn't contact is no negotiations and this is now in the hands of cybercriminals. This is a warning to all companies if you see yourself posted here to reach us. This is the only ammount we have on are servers due to migrating dmca and ignore abuse infrastructure. They were breached on 04/01/2026 and they know they were breached because they closed the s3 bucket starbucks-prod.
- GLOBALLeak Siteas victim2026-04-01
StarBucks Failed to reach out to us and didn't pay even $500,000 when we know they can afford it. It's not even that much we were asking for. Since you didn't contact is no negotiations and this is now in the hands of cybercriminals. This is a warning to all companies if you see yourself posted here to reach us. This is the only ammount we have on are servers due to migrating dmca and ignore abuse infrastructure. They were breached on 04/01/2026 and they know they were breached because they closed the s3 bucket starbucks-prod.
- GLOBALLeak Siteas victim2026-04-01
StarBucks Failed to reach out to us and didn't pay even $500,000 when we know they can afford it. It's not even that much we were asking for. Since you didn't contact is no negotiations and this is now in the hands of cybercriminals. This is a warning to all companies if you see yourself posted here to reach us. This is the only ammount we have on are servers due to migrating dmca and ignore abuse infrastructure. They were breached on 04/01/2026 and they know they were breached because they closed the s3 bucket starbucks-prod.
- Maine State AGas victim2026-03-12
Starbucks Corporation reported a data breach affecting 889 individuals, including 5 in Maine. Unauthorized access occurred between Jan 19 and Feb 11, 2026, via phishing impersonating Partner Central. Compromised data included names, SSNs, DOBs, and financial account numbers. Notices sent March 10, 2026.
- Massachusetts State AGas victim2026-03-12
Starbucks Corporation notified Massachusetts residents that an unauthorized third party accessed certain Partner Central accounts after obtaining login credentials via impersonation websites. Affected data may include name, SSN, date of birth, and financial account/routing numbers. Starbucks engaged experts, notified law enforcement, and is offering 24 months of Experian IdentityWorks.
- New Hampshire State AGas victim2026-03-12
Starbucks Corporation notified the New Hampshire Attorney General on March 12, 2026, of a security breach affecting 4 NH residents. Starbucks became aware on Feb 6, 2026, that an unauthorized third party accessed employee accounts via phishing (impersonating Partner Central websites). Impacted data included names, SSNs, DOBs, and financial account/routing numbers. Starbucks reset credentials, engaged experts, notified law enforcement, and offered 24 months of credit monitoring.
- Indiana State AGas victim2026-03-10
Starbucks Corp dba Starbucks Coffee Company reported a data breach to the Indiana Attorney General. The breach occurred on 2026-02-06 and was reported on 2026-03-10. 25 Indiana residents were affected. 889 individuals affected in total.
- Indiana State AGas victim2026-03-10
Starbucks Corp dba Starbucks Coffee Company reported a data breach to the Indiana Attorney General. The breach occurred on 2026-02-06 and was reported on 2026-03-10. 25 Indiana residents were affected. 889 individuals affected in total.
- Nebraska State AGas victim2026-03-10
Starbucks Corporation notified Nebraska AG of a phishing incident discovered on February 6, 2026, where unauthorized parties accessed Starbucks Partner Central accounts via impersonation sites. Affected data included names, SSNs, DOBs, and financial account/routing numbers. Starbucks engaged experts, notified law enforcement, and offered 24 months of Experian IdentityWorks.
- Massachusetts State AGas victim2008-11-18
Starbucks Coffe Company reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2008-11-18. 1,686 Massachusetts residents were affected. The report records the breach type as electronic.